BIOC
Informational
✕
User creation or modification via /etc file
Attackers may create new users or modify existing users by directly modifying /etc/passwd and /etc/shadow.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Create Account (T1136)
Indicator:
File file path = /etc/shadow , /etc/passwd AND action type = write
Preventable: yes